This IP address has been reported a total of
8
times from
8 distinct
sources.
89.34.90.135 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 7
reports;
France
with 1
report.
The most common categories in these recent reports were:
Port Scan
5
times;
Brute-Force
3
times;
Hacking
2
times;
IoT Targeted
1
time;
Bad Web Bot
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Honeypot trap triggered: unsolicited TCP connection(s) to unused port(s) 3389 on a host running no s ...
show moreHoneypot trap triggered: unsolicited TCP connection(s) to unused port(s) 3389 on a host running no such service. There is no legitimate reason to connect to these ports.
Observed 1 connection(s) from 2026-10-05T15:48:16Z to 2026-10-05T15:48:16Z UTC.
2026-10-05T15:48:16Z tcp/3389 data: \x03\x00\x00+&\xfd\x00\x00\x00\x00\x00Cookie: mstshash=hello \x01\x00\x08\x00\x03\x00\x00\x00 (non-printable bytes hex-escaped)
Connection was blocked automatically at the firewall. Reported by an automated honeypot.
show less
Port scan: unsolicited TCP connection (handshake completed) to a decoy port with no production servi ...
show morePort scan: unsolicited TCP connection (handshake completed) to a decoy port with no production service at 2026-10-05 16:15:14 UTC. Destination port probed: tcp/3389 (RDP). Source blocked. - Lumerux Defense (lumerux.com), automated report. Contact: [email protected]show less
RDP brute-force / credential stuffing: 13 failed Windows logons (Event ID 4625) against 12 of our se ...
show moreRDP brute-force / credential stuffing: 13 failed Windows logons (Event ID 4625) against 12 of our servers (NL), first seen 2026-10-05 15:57 UTC. Blocked automatically.
show less
Brute-Force
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ